We've got a new blog out looking at Kubernetes versions in use in real-world clusters, and it's actually quite good news from a security perspective.
securitylabs.datadoghq.com/articles/a-2...
@smarticu5.bsky.social
Cloud-native offsec at AmberWolf
We've got a new blog out looking at Kubernetes versions in use in real-world clusters, and it's actually quite good news from a security perspective.
securitylabs.datadoghq.com/articles/a-2...
Thought this was a reply to @rawkode.dev at first.
25.10.2025 14:55 β π 3 π 0 π¬ 1 π 0You've got just over a week to contribute feedback for the new OWASP Kubernetes Top 10 docs.google.com/forms/d/e/1F... . Thanks to all the people who have taken the time to contribute already!
23.10.2025 12:34 β π 13 π 6 π¬ 0 π 0Just under a week left until kcduk.io, hosted this year in beautiful Edinburgh. If you havenβt got a ticket yet, there are still some available. I can guarantee some excellent company and talks. Weather may vary, but the cityβs still pretty in the drizzle.
15.10.2025 20:34 β π 0 π 0 π¬ 0 π 0Good luck coming up with an effective keymap for that bad boy.
15.10.2025 19:51 β π 1 π 0 π¬ 2 π 0This is just great.
04.10.2024 06:56 β π 65 π 21 π¬ 3 π 5Please enjoy today, 25/9/2025, the last square date until 2116 (5^2/3^2/45^2).
25.09.2025 07:38 β π 358 π 163 π¬ 7 π 6My talk at @containerdays.bsky.social this week was on Kubernetes and post exploitation. I've had a couple of requests for a companion blog post, so here it is. The post looks at some things attackers might do in clusters they've compromised to retain access.
raesene.github.io/blog/2025/09...
The next Cloud Native and Kubernetes Edinburgh meetup is next week (Weds)! We have a top line-up with @thebsdbox.co.ukΒ doing a deep dive on k8s networking and Ballie Gifford talking about their k8s journey.
Completely agreed. Itβs possible to do multi-tenancy securely, as long as youβre aware of the edge cases which look safe but arenβt. Having processes, monitoring, and guardrails in place helps hugely with not opening up new attack vectors.
01.09.2025 18:29 β π 1 π 1 π¬ 0 π 0Unsurprisingly, I have opinions about Kubernetes, particularly when it comes to multitenancy and how easy it is to break out of common deployments. Today I wrote about them for @amberwolfsec.bsky.social
blog.amberwolf.com/blog/2025/se...
Babe wake up new punk rock dinosaur just dropped. arstechnica.com/science/2025...
29.08.2025 14:56 β π 0 π 0 π¬ 0 π 0A pika sits on a mossy rock.
Tighter crop of the same pika, focusing on its head.
An even tighter crop, focusing more on the pika's eye.
An extremely tight crop of the pika's eye, emphasizing their reflection of an early morning mountain scene.
"Pat, why do you carry that ridiculous 600mm lens on long hikes?"
Buddy, I can see mountains reflected in the eyes of a trailside pika.
www.stepsecurity.io/blog/supply-...
27.08.2025 14:37 β π 3 π 2 π¬ 0 π 0Iβve been considering making the switch from iPhone for a Pixel 10. Of course I managed to drop and smash the iPhone as soon as Iβd clicked a trade in valuation.
25.08.2025 09:43 β π 1 π 0 π¬ 0 π 0Gutted to be missing this one!
17.08.2025 16:02 β π 0 π 0 π¬ 0 π 0Is your company hiring? Would I be useful to your team?
I think I'm ready to open discussions for 2026.
I still have commitments to finish over the next 6 months, but let's start talking.
I'm in no rush and looking to find the right product / team / company.
RTs appreciated
The camera can also act as temporary glasses when the real glasses were sat down somewhere safe, and then apparently vanished from existence.
16.08.2025 16:20 β π 1 π 0 π¬ 0 π 0How did you not just melt in the heat!?
21.06.2025 18:13 β π 2 π 0 π¬ 1 π 0Give a talk at KCD Edinburgh! You donβt even have to be funny (but it helps). CFP here: kcduk.io
07.05.2025 16:34 β π 2 π 3 π¬ 0 π 0Heck yes, this is incredible!
18.05.2025 19:07 β π 3 π 0 π¬ 0 π 0Some say the learning curve for Kubernetes is steep. Try the walk up Calton Hill!
28.04.2025 13:09 β π 0 π 1 π¬ 0 π 0Some musings on the use of the βexecβ directive in a kubeconfig, and how they might be useful to a red teamer or other nasty internet person: blog.iainsmart.co.uk/posts/kubect...
28.04.2025 14:07 β π 2 π 0 π¬ 0 π 0If anyone at #KubeConEU hasn't ever tried a Tunocks caramel wafer, hit me up. I'm travelling prepared.
02.04.2025 04:19 β π 6 π 1 π¬ 1 π 0If you're into variant sudoku, the daily from Cracking the Cryptic's discord is an excellent puzzle today. sudokupad.app/9f1izfy5tg
01.04.2025 16:16 β π 0 π 0 π¬ 0 π 0Gutted to only be at two days of #KubeCon this year. Flying down tomorrow for a swift 36 hours in London catching up with some wonderful people. /honk remotely to everyone already there!
01.04.2025 09:00 β π 2 π 0 π¬ 1 π 0Does anyone who follows me happen to run a blog or similar which they spellcheck with cspell, and have a custom dictionary of container/Linux words?
Apparently the git repo I just ran it on has several hundred typos, but most of those are just "suid" or "containerd" or similar.
After CVE-2024-9042 dropped yesterday, I had a play about to see if I could reproduce the vuln. Spoiler alert, yes I could. I've just published some notes over on the @amberwolfsec.bsky.social blog
blog.amberwolf.com/blog/2025/ja...
Securi-Tay tickets confirmed! That's a conference planned for Feb, March, and April.
12.01.2025 19:24 β π 2 π 0 π¬ 0 π 0Happy Christmas everyone!
Does anyone know if the meeces ever got their cheeses?